Skip to content
Security & Trust

Malware aimed at Ukraine was reworked repeatedly, from July 2024 to April 2026

ESET traces MatchBoil, used by UAC-0099, through upgrades meant to evade security tools and gather more data

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Malware aimed at Ukraine was reworked repeatedly, from July 2024 to April 2026
In brief
  • ESET reports that UAC-0099, a group it believes likely works in Russia's interests, has been developing its MatchBoil malware since at least July 2024. All infections ESET observed were in Ukraine.
  • The authors kept modifying the tool to evade security software, with a newer version as recent as April 2026. A rule written for one version may not fit the next.
  • Ask your security team how detection rules adapt when an attacker keeps changing a tool, and how email links and downloaded archives are handled.

Defenders tend to picture malware as a finished object that gets discovered, named and blocked. New research from ESET describes something different. MatchBoil behaves like a product with release cycles, and its builders kept shipping updates.

The lesson here is that a detection rule is a snapshot of a moving target. A tool that changes with each release is better watched for what it does than for what it is called.

What ESET found

ESET, the Slovak security firm, said in a report on Thursday that MatchBoil is used by a group tracked as UAC-0099. ESET believes the group is likely working in Russia's interests. The Record reported the findings.

The firm's earliest sightings were at several transportation companies in July 2025, with detections continuing into August. A manufacturer followed in December 2025, and an energy-sector company in June 2026. Every infection ESET has observed was in Ukraine.

The group itself is older than the tool. ESET dates its activity to 2022 at the earliest, and CERT-UA, Ukraine's computer emergency response team, first reported on it in June 2023. Its main targets have been Ukrainian government bodies, financial institutions and media outlets.

July 2024
Earliest MatchBoil development ESET traced
Source: ESET, as reported by The Record (October 8, 2026)

How the infection works

The entry point is a phishing email with a link. Clicking it downloads an archive, which is a bundle of files. Those files run a chain of steps that ends with MatchBoil running on the victim's computer.

Once there, MatchBoil does three jobs. It collects details about the infected machine. It pulls down more malicious software from a server the attackers control. And it sets up persistence, which means it stays in place after the computer restarts.

That makes it a downloader: a small first-stage tool whose value lies in what it brings in next. CERT-UA described an August 2025 campaign in which phishing emails posed as Ukrainian court summonses. MatchBoil profiled each machine and delivered further malware. One piece was the MatchWok backdoor, which lets attackers run commands remotely. Another was the Dragstare stealer, which can take browser passwords, cookies and files from the desktop.

The timeline, and what it does and does not show

ESET traced the malware's development to July 2024. Its earliest observed infections came in July 2025. CERT-UA published its first public description of MatchBoil in August 2025, shortly after those first sightings.

The report does not say MatchBoil was used against targets before July 2025. So the gap between July 2024 and mid-2025 shows how long the tool was being built, not how long it was in use.

August 2025
First public documentation by CERT-UA
Source: CERT-UA, as reported by The Record (October 8, 2026)

The real story is the iteration

What the evidence does support is a steady cycle of change. Over the period ESET studied, the authors repeatedly reworked the malware. They made it harder for security software to spot and examine, polished the way it fools victims, and widened what it gathers about infected computers.

ESET's researchers called each release a step up from the one before. They said the pace points to a tool the group values and plans to keep developing. That is ESET's judgment. It also means a block list built against an early version may not describe a later one.

April 2026
Newest MatchBoil version ESET observed
Source: ESET, as reported by The Record (October 8, 2026)

Where the disguise slips

One variant found in late 2025 carried a decoy. If a person launched the file by hand, a daily-planner window appeared, apparently to make the program look harmless. It was not convincing. The planner had two fields both labeled "Today", and a typo in its title made it look like a tool for planning milk consumption.

The detail is amusing. It also shows the group put effort into appearances, even when the result was poor. WebPulse would not read it as a sign of weak code, and the source does not suggest that either.

What leaders should ask

The sources do not say MatchBoil has been used outside Ukraine. Neither ESET nor CERT-UA has said how many organizations or people UAC-0099 has compromised. The questions below are WebPulse's interpretation, not findings from the report.

First, ask how your email and web defences treat a link that leads to a downloaded archive. This attack chain starts with one click, so that step deserves scrutiny.

Second, ask how fast your detection tools update when attackers change a known tool. A rule that catches version one tells you little about version five.

Third, ask whether your monitoring looks for behaviour, such as a program that collects system details, fetches new software and sets up persistence. Those actions can stay constant even when the code changes.

Fourth, if you operate in transport, manufacturing or energy, ask whether your threat intelligence covers regional groups and not only headline campaigns. ESET's observed victims were all Ukrainian, but these sectors exist in many countries.

A tool that is rebuilt release after release cannot be tracked by its last signature alone. Teams that track what it does stand a better chance of keeping pace.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Record.

Share this insight